Description
Deactivate an access policy in PAM Core. A deactivated policy stops applying the access it defines, without being deleted.
This action is the only way to suspend a policy. The active field can't be sent in POST | Create access policy, PUT | Update access policy by [id], or PATCH | Partially update access policy by [id].
Deactivating is the reversible alternative to DELETE | Delete access policy by [id]. Reactivate the policy with POST | Activate access policy.
A deactivated policy can't be edited. Update requests against an inactive policy are rejected with 409 and the code api.resource.inactive, so the policy has to be reactivated before any further change, which makes its access live again. Apply your changes before deactivating.
Prerequisites
- An application with the Access Policy (V2) authorization granted by the administrator in A2A, and its PAM resource permission set to Read and write. For more information, access How to manage authorizations in A2A.
- A valid OAuth 2.0 access token. For more information, access How to authenticate an application in A2A.
- The access policy must be active. Deactivating an already inactive policy returns
409.
An access token carries only the authorizations that existed when it was generated. After the administrator enables Access Policy (V2), generate a new token for the application, an existing token won't gain the new authorization.
Request
POST /api/v2/pam/access-policies/{id}/deactivate
Path parameters
| Field | Type | Required | Description |
|---|---|---|---|
id |
integer | Yes | Unique identification code of the access policy. Note: this value is assigned by Segura® in POST | Create access policy. |
The request has no body.
Example request
POST {{url}}/api/v2/pam/access-policies/3001/deactivate
Response
HTTP/1.1 204 No Content
The response has no body. To confirm the new state, retrieve the policy with GET | List an access policy by [id].
Errors
| HTTP code | Message | Possible cause | Solution |
|---|---|---|---|
401 |
api.auth.token.invalid |
The access token is missing or has expired. | Request a new access token. |
403 |
api.permission.denied |
The authorization doesn't have permission to update access policies. | Ask the administrator to check the Access Policy (V2) authorization and the PAM resource permission in A2A, then generate a new token. |
404 |
api.resource.not_found |
The access policy doesn't exist, or it's outside the scope of the authorization. | Check the identification code sent in the path. |
409 |
api.resource.conflict.already_inactive |
The access policy is already inactive. | No action is needed, the policy is already in the requested state. |
429 |
rate_limit_exceeded |
The request rate limit was exceeded. | Reduce the request rate and try again. |
500 |
api.internal.error |
Internal server error. | Contact the Segura® support team. |
Example error response
409 the policy is already inactive:
{
"error": {
"code": "api.resource.conflict.already_inactive",
"message": "Access policy is already inactive."
}
}
This action isn't idempotent. Repeating it on a policy that's already inactive returns 409 rather than 204. Retrieve the policy's current state before retrying a request whose outcome you're unsure of.
For authentication error messages and the 403 versus 404 policy, access API v2 - Conventions and shared behaviors.